700-765 Sample Questions & Answers
The threat landscape ties with the broader security-solutions portfolio for the heaviest weight, alongside visibility and enforcement through AnyConnect and ISE, advanced threats like malware and ThreatGrid, NGFW and NGIPS network security, IoT security, and Zero Trust.
Launch the full 700-765 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Visibility and Enforcement · Describe Cisco ISE elements
A university needs to provide differentiated network access for students, faculty, and guests. Faculty should have access to sensitive research databases, students to the general academic network, and guests to internet-only. The access rights must be applied consistently across both wired and wireless networks. Which Cisco product is the cornerstone for creating and enforcing these identity-based access policies?
Show answer & explanation
Correct answer: B
Cisco Identity Services Engine (ISE) is the core component for network access control (NAC). It centralizes and automates policy enforcement based on user identity (who), device type (what), location (where), and time (when). ISE integrates with directory services like Active Directory to identify users, assign them to groups (students, faculty), and then enforce policies (e.g., VLAN assignment, downloadable ACLs) on network devices to grant the appropriate level of access.
- Question 2Advanced
Advanced Threat Protection · Explain Advanced Malware Protection elements
A security analyst is investigating an alert from Cisco Secure Endpoint. The alert indicates that a legitimate-looking process on a user's machine,
powershell.exe, has made a network connection to a known command-and-control (C2) server. What feature of Advanced Malware Protection (AMP) allows it to detect this type of malicious activity even when traditional file-based malware is not present?Show answer & explanation
Correct answer: B
The Malicious Activity Protection (MAP) engine is a behavioral protection component within Cisco Secure Endpoint. It focuses on detecting fileless malware and malicious behaviors, such as a legitimate process (powershell.exe) being used for malicious purposes (connecting to a C2 server). File Reputation would not flag this, as
powershell.exeis a trusted file. Sandboxing analyzes files, not necessarily the behavior of already-running processes. The MAP engine specifically looks for these malicious behavioral patterns in real-time. - Question 3Beginner
Threat Landscape and Security Issues · Key cybersecurity challenges facing organizations
A financial institution is suffering from 'alert fatigue' due to its large number of disconnected security tools. Each tool generates its own alerts, forcing the security operations team to manually correlate data across multiple consoles to understand the scope of an attack. This process is slow and error-prone. This situation is a primary example of which key cybersecurity challenge?
Show answer & explanation
Correct answer: C
This scenario perfectly illustrates the challenge of a fragmented security architecture. When security tools do not integrate, they create data silos. This forces manual correlation, slows down response times (Mean Time to Respond - MTTR), and leads to alert fatigue, where important alerts can be missed. The core problem is the lack of integration between tools from multiple vendors, not necessarily the attack surface or staff shortages, although those are also challenges.
- Question 4Beginner
Cisco Zero Trust · Explain the value of zero trust architecture
True or False: In a Cisco Zero Trust architecture, once a user and their device have been authenticated and authorized for initial access, they are considered trusted for the duration of their session and do not require further verification.
Show answer & explanation
Correct answer: B
A core principle of Zero Trust is 'never trust, always verify.' This means trust is not granted for an entire session. Instead, it must be continuously reassessed. A device's security posture could change mid-session (e.g., malware infection), or user behavior could become anomalous. Therefore, verification must be an ongoing process, not a one-time event.
- Question 5Advanced
Cisco Security Solutions Portfolio · Comprehensive security architecture
Case Study: MedCare Diagnostics
Company Background:
MedCare Diagnostics is a rapidly growing healthcare provider with a central hospital, 20 remote clinics, and an increasing number of healthcare professionals working from home. They handle sensitive Protected Health Information (PHI) and must comply with HIPAA regulations. Their network consists of a mix of corporate-owned laptops, medical IoT devices (e.g., infusion pumps, patient monitors), and BYOD devices for non-clinical staff.Current Situation:
MedCare's security is managed by a small IT team using a traditional perimeter firewall at the hospital and basic routers at the clinics. Remote access is provided via a legacy VPN solution with no device posture checking. They have experienced several security incidents, including a malware outbreak at a remote clinic that spread to the main hospital network. They have no visibility into traffic between devices on the same network segment (east-west traffic) and cannot enforce access policies based on user role or device type.Requirements:
The CISO has mandated a new security architecture based on Zero Trust principles. The key requirements are:- Establish strong identity verification for all users and devices connecting to the network.
- Implement micro-segmentation to isolate critical systems and prevent the lateral movement of threats.
- Gain visibility into all network traffic, including encrypted traffic, without compromising performance.
- Ensure secure access for remote workers with continuous device health verification.
- Centralize security policy management and incident response.
Question:
As a Cisco system engineer, which combination of products provides the most comprehensive solution to meet all of MedCare's requirements?Show answer & explanation
Correct answer: C
This solution directly addresses all five requirements. ISE provides identity-based NAC and enables TrustSec for micro-segmentation (Requirement 1 & 2). Secure Access by Duo ensures strong, posture-aware remote access (Requirement 4). Stealthwatch provides comprehensive network visibility, including encrypted traffic analysis (Requirement 3). Finally, SecureX provides the centralized platform for management and response (Requirement 5). This combination forms the foundation of a Cisco Zero Trust architecture for the workplace.
- Question 6Advanced
Visibility and Enforcement · Cloud security solutions
A system engineer is explaining Cisco's approach to data center security. The customer wants to implement a security policy that follows the application workload, regardless of whether it moves from a virtual machine in the on-premises data center to a container in a public cloud. Which Cisco solution is designed to provide this application-centric, environment-agnostic micro-segmentation?
Show answer & explanation
Correct answer: C
Cisco Secure Workload is specifically designed to address this use case. It discovers application dependencies and provides a consistent policy enforcement model across any infrastructure: bare metal, virtual machines, and containers, both on-premises and in the cloud. Its policies are tied to workload attributes, not network constructs like IP addresses, allowing security to follow the workload wherever it goes. While ACI and TrustSec are powerful segmentation tools, they are primarily focused on the network infrastructure layer, whereas Secure Workload is workload-centric and environment-agnostic.
- Question 7Intermediate
Advanced Threat Protection · Describe threat intelligence capabilities
Which statement accurately describes the relationship between Cisco Threat Intelligence Director (TID) and Cisco Talos?
Show answer & explanation
Correct answer: B
Cisco Talos is the threat intelligence organization that performs research and generates intelligence feeds. Threat Intelligence Director (TID) is a feature within the Firepower Management Center (FMC) that acts as an intelligence aggregator. It consumes intelligence from Talos, but also from third-party feeds via standards like STIX/TAXII. TID then allows administrators to use this aggregated intelligence to create and enforce policies on Firepower devices, effectively operationalizing multiple intelligence sources.
- Question 8Beginner
Threat Landscape and Security Issues · Role of digitization in cybersecurity
The proliferation of mobile devices, cloud applications, and IoT has fundamentally changed network boundaries. Which term best describes the impact of this trend on the traditional, perimeter-focused security model?
Show answer & explanation
Correct answer: B
Digitization, characterized by the adoption of mobile, cloud, and IoT, means that users, data, and applications are no longer confined within a well-defined network perimeter. This decentralization massively expands the attack surface—the sum of all possible entry points for an attacker. The traditional model of a strong perimeter with a trusted interior is no longer viable because the 'perimeter' is now everywhere, effectively dissolving it.
- Question 9Intermediate
IoT Security · Components of Cisco IoT security
A hospital is deploying thousands of connected medical devices (IoT), such as IV pumps and patient monitors. The security team's primary concern is that these devices often cannot run traditional security agents and may have unpatched vulnerabilities. They need a way to monitor the behavior of these devices and detect anomalies, such as a pump attempting to connect to an external website. Which Cisco security solution provides agentless visibility and threat detection for such IoT devices by analyzing network traffic?
Show answer & explanation
Correct answer: C
Cisco Stealthwatch is a network visibility and security analytics solution that is ideal for securing IoT devices. It operates by collecting and analyzing network telemetry (like NetFlow) from network infrastructure. This agentless approach allows it to baseline the normal behavior of all devices on the network, including those that cannot run agents. When a device deviates from its baseline, such as an IV pump communicating with an unusual destination, Stealthwatch flags it as an anomaly, alerting security teams to a potential compromise.
- Question 10BeginnerSelect 2
Cisco Zero Trust · Cisco Zero Trust outcomes
A key outcome of a Cisco Zero Trust for the Workplace strategy is achieving 'Trusted Access'. What are the two primary components that must be verified to establish this trusted access? (Select TWO)
Show answer & explanation
Correct answers: B, D
Verifying the user's identity, typically through strong multi-factor authentication (MFA), is a foundational step in establishing trusted access.
Alongside verifying the user, Zero Trust requires verifying the trustworthiness of the device they are using. This includes checking its security posture, such as whether the OS is patched, disk encryption is enabled, and security software is running.
Ready for the real thing?
The full 700-765 simulator has every exam-style question, timed mode, and instant scoring.